Thriveweb's disclosures center on a small line of WordPress gallery and e-commerce plugins, including PhotoSwipe Masonry Gallery, Pinzolo, and WooSwipe WooCommerce Gallery, where the recurring vulnerability signal is cross-site scripting tied to improper input neutralization in web-page generation. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thriveweb over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45066HIGH Auth. (subscriber+) Broken Access Control vulnerability in WooSwipe WooCommerce Gallery plugin <= 2.0.1 on WordPress. | Nov 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2023-2813MEDIUM All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business | Sep 4, 2023 | 6.1 | 25 | NO | YES |
CVE-2022-0750MEDIUM The Photoswipe Masonry Gallery WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the thumbnail_width, thumbnail_height, max_im | Mar 23, 2022 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thriveweb.
Media articles that mention a CVE ID that affects a product developed by Thriveweb — matched by CVE ID, not by vendor name.